GitHub 红队武器库🚨
14.3K subscribers
25 photos
9 videos
27.3K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #CVE

📦 项目名称: CVE-2025-45737
👤 项目作者: Shinn-Home
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 13:52:49

📝 项目描述:
利用CVE-2025-45737漏洞,实现提权

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: metasploitable2-php-cgi-exploit
👤 项目作者: mujtaba815
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 13:32:38

📝 项目描述:
Exploited a known RCE vulnerability (PHP-CGI Argument Injection, CVE-2012-1823) on Metasploitable2 using Metasploit Framework, gained a shell, and documented post-exploitation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: XSS-Hunter
👤 项目作者: mizazhaider-ceh
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 13:33:47

📝 项目描述:
Exam-grade reflected-XSS fuzzer: threaded, grep-filter, Burp-aware, auto-detect. Python, zero dependencies.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2026-42589xCVE-2026-40281-PoC
👤 项目作者: codeb0ssx
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:05:55

📝 项目描述:
CVE-2026-42589 & CVE-2026-40281 - GotenBerg

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: ghidra-skill-for-dsh
👤 项目作者: Cristallin2006
🛠 开发语言: Python
⭐ Star数量: 7 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-02 11:42:24

📝 项目描述:
dsh (DeepSeek Harness) 逆向 agent skill 家族:Ghidra headless daemon + 分诊/脱壳/静态/漏洞/动态/流量/安卓七场景 | Reverse-engineering agent skills: triage, unpacking, decompile, pwn audit, pcap forensics, APK analysis

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: netscaler_threat_hunt_helper
👤 项目作者: orjanj
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:50:23

📝 项目描述:
NetScaler CTX697096 Threat Hunt Helper (IoC scanner) - CVE-2026-88771, CVE-2026-88772

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-55559
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:33:27

📝 项目描述:
Unauthenticated RCE in Yamcs mission control via YAML injection in reconfigureInstance()

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: huellanativa
👤 项目作者: jocelin-portafolio
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:32:22

📝 项目描述:
SPA en JavaScript vanilla: perfiles sensoriales para niños neurodivergentes, e-commerce con carrito persistente y monitor IoT simulado. Renderizado seguro sin innerHTML (anti-XSS).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2026-40281-exploit
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:26:07

📝 项目描述:
Gotenberg 8.30.1 unauthenticated RCE exploit

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: PenPot-RCE
👤 项目作者: overgrowncarrot1
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:06:40

📝 项目描述:
Penpot <2.15.0 allows for unathenticated RCE CVE-2026-45805

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-analysis
👤 项目作者: sarfraz432
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:39:11

📝 项目描述:
Malware analysis, information on malware, reversing, required scripts, yara rules, configuration extractors.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: YaraRuleDraftReview
👤 项目作者: dhtfish-98
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 15:41:10

📝 项目描述:
Bounded offline YARA rule drafting from caller-labeled byte corpora with real native validation and explicit uncertainty.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: arc-studio-gitpython-cve-poc
👤 项目作者: hackthesoul
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 16:20:06

📝 项目描述:
Benign PoC for GitPython CVE-2026-87817 (bug bounty research, arc-bbp)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: Abducted-HTB-Writeup
👤 项目作者: timgad794
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 16:19:18

📝 项目描述:
🔴 HackTheBox Abducted (Medium) — CVE-2026-4480 (Samba %J) → rclone reveal → SMB-Symlink → systemd Drop-in → Root

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC #CVE #metadata

📦 项目名称: mcp-remote-oauth-security
👤 项目作者: playb0t
🛠 开发语言: Unknown
⭐ Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-02 16:51:43

📝 项目描述:
Seven evidence-bounded OAuth trust-boundary security advisories for geelen/mcp-remote, reviewed through 0.1.38.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #攻防演练 #渗透

📦 项目名称: redforge
👤 项目作者: f5dt1artum
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 16:57:55

📝 项目描述:
这是一个面向渗透测试与攻防演练的渗透测试与攻防演练平台。长期目标是提供资产发现与指纹识别、端口与服务测绘、漏洞模板匹配、凭证探测、载荷生成、攻击链编排、授权边界强制和结果评分,把攻防演练沉淀为可复用平台。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: IronClaud-Security-WebScanner
👤 项目作者: Ganesh030106
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 16:30:59

📝 项目描述:
IronClad Security Command Center is an advanced, enterprise-grade web application vulnerability scanner and dynamic Web Application Firewall (WAF) suite.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: vsftpd-2.3.4-rce-assessment
👤 项目作者: Spidey1919
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 16:48:34

📝 项目描述:
Penetration testing portfolio: FTP vulnerability assessment & exploitation in isolated lab. Demonstrates network reconnaissance, CVE-2011-2523 validation, and post-exploitation verification. Complete methodology with evidence, findings, and remediation guidance.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2026-104826
👤 项目作者: KiwKNR
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 16:14:40

📝 项目描述:
CVE-2026-104826: path traversal to RCE in DropzoneFileExplorer chunked upload handler

🔗 点击访问项目地址
TG必备的搜索引擎,快搜kuai帮你发现有趣群组、频道、视频、音乐、电影、新闻 | Find cool stuff all in one bot!

机器人:@kuai @kuaia @kuaiaa

👉 https://t.me/kuai?start=a_3URZVD0
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored

📦 项目名称: Instatic-Stored-XSS-CVE-2026-103931
👤 项目作者: overgrowncarrot1
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 17:18:27

📝 项目描述:
CVE-2026-103931

🔗 点击访问项目地址